2026 CVE Vulnerabilities

56,211 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1227HIGH7CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclo...
CVE-2026-1226HIGH7CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintende...
CVE-2026-0910HIGH8.8The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13...
CVE-2026-1458HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18...
CVE-2026-1456HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 th...
CVE-2026-0958HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2026-1560HIGH8.8The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to...
CVE-2026-1507HIGH8.7The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely c...
CVE-2026-21349HIGH7.8Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2026-25613HIGH7.1An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo...
CVE-2026-25610HIGH7.1An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
CVE-2026-25506HIGH7.8MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can ...
CVE-2026-21353HIGH7.8DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resul...
CVE-2026-21352HIGH7.8DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr...
CVE-2026-21347HIGH7.8Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re...
CVE-2026-21346HIGH7.8Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arb...
CVE-2026-21345HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2026-21344HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2026-21343HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2026-21342HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-21341HIGH7.8Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-1850HIGH7.5Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
CVE-2026-1849HIGH7.5MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents...
CVE-2026-1848HIGH8.2Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i...
CVE-2026-1847HIGH7.5Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now